Quishing: QR code scams explained
A QR code is a link you cannot read. That is its convenience and its whole vulnerability, because you do not see where it goes until your phone is already going there.
What quishing is
Quishing is phishing delivered through a QR code rather than a clickable link. The name follows smishing for SMS and vishing for voice.
The mechanism is not new and the QR code is not the clever part. With an ordinary phishing email you can read the link before you click it, and a domain like bank-secure-verify.example gives itself away. With a QR code there is nothing to read. The inspection step that catches ordinary phishing is simply removed from the process.
That is the entire innovation, and it is enough. The attack that follows is the same as always: a convincing fake login page, a fake payment page, or a prompt to download something.
Where it actually happens
Two categories, and they need different defences.
Physical tampering
Someone prints a sticker and places it over a real code. The FBI's Internet Crime Complaint Center issued a public service announcement in January 2022 warning that criminals were tampering with both digital and physical QR codes, naming parking meters, cryptocurrency ATMs and restaurant payment kiosks specifically. The Federal Trade Commission has separately warned about scammers covering parking meter QR codes with their own.
This is still happening. In August 2026, police in New Westminster, British Columbia warned that fraudulent "scan to pay" stickers had been attached to parking meters across the city, after multiple people reported unauthorised withdrawals following a scan. Reporting on that case noted one victim losing $2,000, and that the city does not use QR codes to collect parking payments at all.
That last detail is the important one, and it is why blanket advice fails. Some cities never use QR codes on meters, so any code you find is fraudulent by definition. Others use them legitimately. New York directs drivers to its official app or the physical meter. The correct habit is not "never scan a meter" but "know how this city takes payment before you arrive at the meter."
Codes that arrive unexpectedly
A QR code in an email is an image, so it slips past filters that would have flagged a suspicious link as text. Codes arriving on unsolicited packages and in messages about unpaid tolls or deliveries follow the same logic. If you did not go looking for it, treat it as unsolicited regardless of who it appears to be from.
Spotting a tampered code
Physical tampering leaves physical evidence, which makes it the easiest variant to defeat.
Check a code before you scan it
Four things you can see without scanning anything. Answer honestly.
Tick anything that applies.
- Is it a sticker? Legitimate codes on meters, menus and kiosks are usually printed directly onto the surface or sit under laminate. A fresh sticker on top is the single clearest signal.
- Does it align with the surrounding artwork? Official codes are laid out with the rest of the design. A code sitting slightly crooked, overlapping a border, or peeling at a corner was added later.
- Does it match the others nearby? On a row of parking meters, one code that differs from the rest is worth a second look.
- Read the URL preview before tapping. Most phone cameras show the destination first. Look for misspellings and unfamiliar domains, and remember that a plausible-looking domain is easy to register.
The one rule that works
All of the advice above helps, and all of it depends on you being alert at the moment you are standing in the rain trying to pay for parking. There is one habit that does not depend on that.
Type the address yourself, or use the official app. Parking, tolls, banks, government services and restaurant chains all publish addresses you can enter directly. Installing a city's parking app from the App Store or Google Play, rather than scanning whatever is stuck to the meter, removes the attack surface completely rather than trying to out-spot it.
This is not an argument against QR codes generally. It is an argument for skipping them in the narrow set of situations where a stranger could have physically placed one and money is about to change hands.
If you already scanned one
- Close the page. If nothing was entered and nothing downloaded, that is usually the end of it.
- If you entered a password, change it on the real service and turn on two-factor authentication.
- If you entered card or bank details, call your card issuer's fraud line and dispute any charges.
- If something downloaded, do not open it, delete it, and run a security scan.
- Report it to the FBI's Internet Crime Complaint Center at ic3.gov and to the FTC at reportfraud.ftc.gov.
- Tell the business or the city whose premises the code was on, so the sticker gets removed for everyone behind you.
If you publish QR codes
The tampering risk is on your customers, but the reputational damage is yours.
- Make the code hard to cover. Print directly onto the surface, laminate it, or etch it. A sticker is easy to place over another sticker.
- Print the destination beside the code in plain text, so a customer can verify where they should be landing, and type it instead if they prefer.
- Check your public codes. Anything on a meter, table, window or kiosk should be inspected on a routine, not after a complaint.
- Say how you take payment on the signage itself. The New Westminster case worked partly because drivers had no way to know the city never used QR payment.
Sources
Every specification figure on this page traces to one of the following. Nothing is stated here that could not be checked against them.
- FBI Internet Crime Complaint Center (IC3), public service announcement of January 2022 on QR code tampering
- Federal Trade Commission, consumer warning on fraudulent parking meter QR codes and fraud reporting
- Reporting on the New Westminster, British Columbia parking meter sticker case, August 2026
Last reviewed 6 September 2026
This page is written and maintained by Cedrick Reese at Ready Utilities, and was checked against current sources on 6 September 2026. The FBI Internet Crime Complaint Center advisory of January 2022 and the Federal Trade Commission's warning about parking meter codes are cited as issued. The New Westminster incident is reported as covered in August 2026, including the reported individual loss and the city's statement that it does not use QR codes for parking payment. Two figures circulating in coverage of this topic, a percentage increase in quishing since 2023 and an average loss per victim, each appeared in only one source during this check and are therefore not repeated here. Scam tactics change, so this page is reviewed against current advisories rather than left to age. It is general information, not security or legal advice.
Common questions
What is quishing?
Quishing is phishing delivered through a QR code instead of a clickable link. The name follows the same pattern as smishing for SMS and vishing for voice calls. The mechanism is identical to ordinary phishing; the QR code just hides the destination until your phone has already begun loading it.
Can scanning a QR code install malware on my phone?
Scanning alone normally just opens a URL. The damage usually comes from what you do next: entering credentials on a fake login page, submitting card details to a fake payment page, or approving a download. Keeping your phone and browser updated reduces the residual risk from the page itself.
How can I tell if a QR code has been tampered with?
Look at the physical code. Legitimate codes on meters, menus and kiosks are usually printed directly onto the surface or sit under laminate. A fresh sticker placed over the top, especially one that is peeling or misaligned with the surrounding artwork, is the clearest warning sign.
Are parking meter QR codes safe?
It depends entirely on the city, which is why a single rule does not work. Some municipalities do not use QR codes for parking payment at all, so any code on the meter is fraudulent by definition. Others use them legitimately. Verify the payment method independently rather than assuming either way.
What should I do if I already scanned a malicious QR code?
Close the page. If you entered a password, change it on the real service and turn on two-factor authentication. If you entered card details, call your card issuer's fraud line and dispute any charges. Report it to the FBI's Internet Crime Complaint Center at ic3.gov and to the FTC at reportfraud.ftc.gov.
Does this mean QR codes are unsafe to use?
No. The QR code itself is a neutral container, and the vast majority are exactly what they claim to be. The risk is specific: codes in public places where a stranger could physically place a sticker, and codes arriving unexpectedly by email or post.